ProofKeel

ProofKeel Trace

Every alert machine-investigated before a human sees it.

Proof, not just alerts — detection, investigation, and court-defensible forensics for self-managed infrastructure.

Event-to-detect SLO
<60s
Golden-tested detection rules
1096
Cold-tier compression vs warm Parquet, measured
3–5×

Why Trace

Investigation-first, evidence-always

Streaming detection

A streaming Sigma-subset engine evaluates events as they arrive — windowed aggregations, per-entity state, cross-source joins — against a 1096-rule catalog mapped to 283 MITRE ATT&CK techniques and tactics. Every rule is golden-tested; nothing waits for a nightly batch.

Forensic proof

Hash-chained manifests, signed daily roots, WORM retention on object lock, and a standalone verifier that checks an evidence export offline — no platform access required. Proof that holds up long after the incident.

An AI analyst on every alert

An AI analyst investigates every alert before a human sees it, on a governed trust path — shadow, then assisted, then autonomous — and only acts alone after clearing a ≥97% gold-set precision gate. When it cannot ground a verdict it returns analysis-unavailable and escalates — it never guesses.

Deep dive

The investigation experience

Humans and the AI analyst work the same way: through governed query APIs, with every step auditable. No separate “AI mode” — one investigation surface, two kinds of investigator.

Three ways to ask

Guided pivots for the alert in front of you, a pipeline syntax for hunts, full SQL when you need it — all over the same governed query APIs the AI analyst uses.

Pivots and auto-timelines

Click any user, host, IP, or hash to pivot. The entity's timeline assembles itself — no manual correlation across sources.

From alert to case

Detections deduplicate and group into cases, enriched with asset, identity, and threat-intel context, then risk-scored — so a queue of hundreds reads as a handful of decisions.

Attacker-controlled content, sandboxed

Raw log payloads are untrusted input and are treated that way: rendered in an isolated origin with no credentials, never in the app itself.

Chain of custody

Evidence you can verify without trusting us

Every export carries a hash-chained manifest. Verify it offline, with your own tools, years later — the chain either checks out or it doesn’t.

Under the hull

Built from scratch for efficiency and scale

ProofKeel Trace was designed in 2026 from a clean sheet, not retrofitted onto a per-GB-licensed engine: immutable segments on object storage, a streaming detection engine, and an open data plane where your data stays yours — built for multi-TB/day ingest.

Disaggregated compute and storage

Stateless readers scale independently of ingest. Query load never competes with the write path.

Immutable segments as the system of record

Data lands in immutable Parquet segments on S3-compatible object storage, each with a needle-index sidecar that can prove a term absent without scanning the segment — cheap, durable, and tamper-evident by construction.

A Rust data plane, end to end

Ingest, detection, indexing, and query run in Rust — no JVM tax, no garbage-collection pauses in the data path.

A cold tier that stays searchable

Unstructured text compresses into template-and-variable archives — measured at 3–5× smaller than the warm Parquet tier — and remains queryable, so retention stops being a budget negotiation.

No lock-in

Built on an open data plane

Events are normalized to OCSF and stored as plain Parquet on S3-compatible object storage — open formats you can query, export, and verify with your own tools. Ingest spans agents and syslog, IPFIX/NetFlow v9 flow records, and an eBPF sensor that applies only signed collection profiles. Your data stays yours.

Pricing research

Which daily ingest band fits your operation?

These are indicative research inputs, not final prices, quotes, or an offer. Choosing a band tells us which volume and price point to validate; it does not reserve service or charge you.

This experiment tests the volume ladder only. Capability tiers, bundles, contract terms, and exact price points remain undecided.

Research estimate

50 GB/day

Free

Daily fleet-wide ingest band with a hard cap. This research assumes no per-endpoint or per-seat charge.

Research estimate

100 GB/day

~$60–75K/yr

Daily fleet-wide ingest band with a hard cap. This research assumes no per-endpoint or per-seat charge.

Research estimate

500 GB/day

~$150K/yr

Daily fleet-wide ingest band with a hard cap. This research assumes no per-endpoint or per-seat charge.

Research estimate

1 TB/day

~$400K/yr

Daily fleet-wide ingest band with a hard cap. This research assumes no per-endpoint or per-seat charge.

Research estimate

5 TB/day

~$1.6M/yr

Daily fleet-wide ingest band with a hard cap. This research assumes no per-endpoint or per-seat charge.

Research estimate

10 TB/day

~$2.7M/yr

Daily fleet-wide ingest band with a hard cap. This research assumes no per-endpoint or per-seat charge.

Early access

Join the waitlist

No spam. We’ll email you exactly once when early access opens. Prefer email? hello@proofkeel.com

By joining, you agree to how we handle your information — see our privacy notice.